-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-rails-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-rails-14.1-jessie-i386.iso 385583fae41f68f2f00adb6a12b7dd26 $ sha1sum turnkey-rails-14.1-jessie-i386.iso 78c6daae678048e4fc6da33221efc8b14df0818b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNwekIAM/kguHYMTIibXGspj1D8OHT 2Ct/kPlrZETmTGPhd1wEr9PL5EAGyk0oBya7P3SrmjylLxzEvUWGv/uB0waEJfq1 Yz16k4c6mS8dJB4RVbFoFwY9Tu+Zh7ePTl8jE/u9bzvNqrcEL6104nocdp7YYNAU W7uNxR3fmoFC1hJsufo85MGIEHe9BSrZLE7y8x7Rj14+0ZrPHKXKVRT9GEUgeDR3 HOPs/1ZLwraGrwm/M3iL/P7b+81rD0x60tIdTqAIXiLJsVS1w42KH05KyO3mj5p0 /GurwJYVpDh7GzGS87BjWf+ctFjzZjeBDn0dj3+qQqAT+xgdLCpXoI44nMa7Jn4= =MLuO -----END PGP SIGNATURE-----